CompTIA SecurityX (CASP+) CAS-
005 Certification Exam Practice
Question Bank - Version 2.0
Advanced-Level Practice
Questions for Security Architects,
Senior Security Engineers, and
Enterprise Security Practitioners
a well detailed one
written and graded A+
upgraded
, 2
Domain 1: Governance, Risk, and Compliance (GRC) – 20% of Exam
Question 1
A multinational organization is implementing a unified compliance framework to address GDPR,
CCPA, and HIPAA requirements simultaneously. Which GRC approach provides the MOST
efficient cross-regulatory compliance management?
A) Maintain separate compliance programs for each regulation
B) Implement a unified controls framework mapped to multiple regulatory requirements
C) Focus exclusively on the most stringent regulation
D) Outsource compliance management to external consultants
-” detailed answer 100 % correct :-”B
Rationale: A unified controls framework mapped to multiple regulatory requirements enables
efficient compliance management by identifying overlapping controls and avoiding duplicate
efforts. Separate programs (A) create redundancy. Focusing only on the most stringent (C)
leaves gaps. Outsourcing (D) doesn't address internal accountability.
Question 2
A security architect is developing a business continuity plan for a global enterprise. Which
metric indicates the maximum acceptable data loss during a disaster scenario?
A) RTO (Recovery Time Objective)
B) RPO (Recovery Point Objective)
C) MTD (Maximum Tolerable Downtime)
D) SLA (Service Level Agreement)
-” detailed answer 100 % correct :-”B
Rationale: RPO measures the maximum acceptable data loss measured in time—how far back
data can be lost without causing unacceptable impact. RTO (A) measures time to recover. MTD
(C) is the maximum total downtime tolerated. SLA (D) is a service commitment.
Question 3
, 3
A security program manager is creating an enterprise risk register. Which risk treatment strategy
involves transferring risk to a third party?
A) Risk Acceptance
B) Risk Mitigation
C) Risk Avoidance
D) Risk Transfer
-” detailed answer 100 % correct :-”D
Rationale: Risk transfer involves shifting risk to a third party, typically through insurance or
outsourcing. Risk Acceptance (A) acknowledges the risk without action. Risk Mitigation (B)
reduces the risk. Risk Avoidance (C) eliminates the risk by avoiding the activity.
Question 4
An organization is implementing NIST SP 800-53 security controls for a federal information
system. Which control family addresses incident response capabilities?
A) AC (Access Control)
B) AU (Audit and Accountability)
C) IR (Incident Response)
D) CP (Contingency Planning)
-” detailed answer 100 % correct :-”C
Rationale: NIST SP 800-53 control family IR (Incident Response) specifically addresses incident
handling, training, testing, and reporting. AC (A) covers access controls. AU (B) covers audit
trails. CP (D) covers contingency planning.
Question 5
A security architect is implementing a third-party risk management program. Which due
diligence activity provides the MOST comprehensive vendor security assessment?
A) Reviewing vendor marketing materials
B) Analyzing vendor SOC 2 Type II reports and conducting on-site audits
C) Checking vendor's website for security certifications
D) Reviewing vendor's stock price and financial reports
-” detailed answer 100 % correct :-”B
, 4
Rationale: SOC 2 Type II reports provide third-party verification of controls over time, and on-
site audits provide direct observation of security practices. Marketing materials (A) are biased.
Website certifications (C) are superficial. Financial reports (D) are irrelevant to security.
Question 6
An organization is developing a data classification policy. Which data classification level requires
the STRONGEST protection controls?
A) Public
B) Internal Only
C) Confidential
D) Restricted / Highly Confidential
-” detailed answer 100 % correct :-”D
Rationale: Restricted or Highly Confidential data requires the strongest protection controls as its
compromise would cause the most significant damage to the organization. Public (A) requires
minimal controls. Internal Only (B) requires moderate controls. Confidential (C) requires strong
controls but not the strongest.
Question 7
A security manager is conducting a risk assessment. Which risk calculation formula correctly
represents Annualized Loss Expectancy (ALE)?
A) ALE = SLE × ARO
B) ALE = AV × EF
C) ALE = SLE + ARO
D) ALE = AV / EF
-” detailed answer 100 % correct :-”A
Rationale: ALE = SLE (Single Loss Expectancy) × ARO (Annualized Rate of Occurrence). Option B
calculates SLE. Options C and D use incorrect formulas.
Question 8